claim-katana[.]network
“Region blocked”
The domain claim-katana.network was identified as a crypto drainer phishing site designed to steal cryptocurrency from victims' wallets. Unlike typical brand impersonation schemes, this site operated without mimicking a specific legitimate service, focusing solely on draining digital assets. As of the latest verification, claim-katana.network has been taken offline, though its prior activity poses residual risks to users who may have interacted with it.
Technical analysis of claim-katana.network revealed limited but notable detection metrics. The domain was flagged by 2 of 95 security vendors on VirusTotal, while Google Safe Browsing did not list it as malicious. It appeared on one security blocklist, PhishDestroy. Registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 18, 2026, the domain resolved to the IP address 172.67.166.130, hosted by Cloudflare, Inc. in Canada. The SSL certificate was issued by Let's Encrypt, and the observed page title was 'Region blocked'. Nameservers were gerald.ns.cloudflare.com and naomi.ns.cloudflare.com, with detected technologies including Cloudflare Browser Insights, Cloudflare, and HTTP/3.
Users who may have connected their wallets to claim-katana.network should immediately revoke all token approvals using a tool like Etherscan's Token Approval Checker or Revoke.cash. Moving remaining funds to a new, secure wallet is strongly advised to prevent further unauthorized transactions. Victims should also monitor their accounts for suspicious activity and report the domain to platforms such as PhishTank, Google Safe Browsing, or their local cybercrime authority to aid in broader threat mitigation.
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-26 02:55:26 UTC
Technologies · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of claim-katana.network · checked Mar 23, 2026
Evidence & External Reports
PD-20260323-931EFA Recipient: abuse@nicenic.net, compliance@icann.org Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive